Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Apples and oranges. When we talk about 128-bit security, we mean that it takes ~2^128 work to break it; not that there's a 2^-128 chance that it is broken.


Most protocols do allow the attacker to choose how many times the defender must win at some game of probability.

If the defender is somehow put in a situation to generate 2^80 primes, then he's in trouble.


Sure, I'd aim for a higher security level in a "attacker can keep asking for new primes until we screw up" scenario.


> When we talk about 128-bit security, we mean that it takes ~2^128 work to break it; not that there's a 2^-128 chance that it is broken.

But it also implies that e.g. the attacker has a 2^-128 chance of randomly guessing a key.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: